standard ACL in the firewall and in the router

Answered Question
Apr 27th, 2010

dear experts,

hello

i know that the standard ACL syntax in the router we mention the SOURCE ip address,right?

but when i read a configuration guid file for the standard ACL in the ASA firewall in cisco.com i found that we mention the DESTINATION

ip address...

so this difference in the same type of ACL  in the router and the ASA is right and logical ?

thanks for your reply,

labib makar

I have this problem too.
0 votes
Correct Answer by Federico Coto F... about 6 years 8 months ago

Hey labib,

I have not realized this until now!

I always use extended ACLs for everything and it's been a while since using a standard ACL.

You are 100% correct and on the ASA, the standard ACL is based on destination (not source) as opposed to IOS.

I've seen standard ACLs on ASA for split-tunneling and for OSPF configuration in route-maps.

Good one!

Federico.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Federico Coto F... Tue, 04/27/2010 - 17:11

Hi,

Standard ACLs always reference the source.

What is the document that you're referring to?

Federico.

labibmakar Tue, 04/27/2010 - 17:54

hi federico,

first thanks for your reply

i sent you the link of the configuration guid that says that in cisco.com in one of the technical document.

and another print screen image from the book i'm reading that says the same. ( the name of the book in the title bar of the printed page)

thanks for your help

labib

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/acl_standard.html#wp1056837

Correct Answer
Federico Coto F... Tue, 04/27/2010 - 18:38

Hey labib,

I have not realized this until now!

I always use extended ACLs for everything and it's been a while since using a standard ACL.

You are 100% correct and on the ASA, the standard ACL is based on destination (not source) as opposed to IOS.

I've seen standard ACLs on ASA for split-tunneling and for OSPF configuration in route-maps.

Good one!

Federico.

labibmakar Tue, 04/27/2010 - 19:02

ok federico it is clear for me now, thanks alot for your efforts

labib

Actions

This Discussion